WaterPlum: Fake Job Interviews Hacked 30,000 Devices

North Korea's employment scams work in both directions. As well as planting fake IT workers inside Western companies, regime-backed operators are now posing as recruiters, and the latest international advisory says the scheme has infected more than 30,000 devices and siphoned off over $10 million.

TL;DR: Law enforcement agencies from Australia, Germany, Japan, and the US issued an advisory on Thursday about WaterPlum, a North Korean campaign in which fake recruiters send coding assignments that backdoor applicants' computers. The operation has infected more than 30,000 devices, compromised more than 7,000 cryptocurrency wallets, and funneled at least $10.71 million to Pyongyang. Below: how the scheme works, what attackers steal, how it ties to the wider fake-IT-worker economy, and how to spot a fraudulent recruiter.

Rows of server racks inside a datacenter

Photo: Carl Lender, CC BY 2.0, via Wikimedia Commons

What Happened

How did the WaterPlum attackers infect devices?

Victims were sent files presented as coding assignments or recruitment tests during a fake interview. Opening those files installed remote access trojans and information stealers, giving attackers persistent access to the computer.

What is the scale of the North Korean fake IT worker problem?

Researchers estimate roughly 100,000 North Korean IT workers are employed or seeking work worldwide, and the scheme is thought to net the regime upwards of $500 million a year.

How can I avoid a fake recruiter scam?

Refuse to download files from unsolicited recruiters, run any coding test in a sandbox, keep your system patched, and treat any request to remote into your machine or share wallet keys as a red flag.

Which countries issued the WaterPlum advisory?

Agencies from Australia, Germany, Japan, and the United States issued the joint advisory, published through the US Internet Crime Complaint Center.

On Thursday, agencies from Australia, Germany, Japan, and the United States issued a joint advisory on an ongoing North Korean campaign tracked as WaterPlum. According to the report, attackers posing as recruiters have infected more than 30,000 devices through fake job interviews and compromised more than 7,000 cryptocurrency wallets, with thefts attributed to the scheme reaching at least $10.71 million.

The target list is specific. WaterPlum operators pursue web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches. During the supposed interview process, victims are instructed to download files presented as coding assignments or other recruitment tests. Opening them backdoors the applicant's computer and installs malware.

Once inside, the attackers deploy remote access trojans (RATs) and information stealers. That gives them persistent access to credentials and other sensitive data long after the fake interview ends. In some cases, the compromised machine later becomes a route into a corporate network when the jobseeker secures legitimate employment.

The advisory, published through the US Internet Crime Complaint Center, spells out the goals in blunt terms. Stolen identity documents let North Korean IT workers impersonate victims and generate foreign currency. Stolen credentials can be used to drain crypto assets, personal data, and trade secrets from an employer, a client, or a contractor. The actors can also use stolen sensitive information for extortion.

The advisory stresses that the operation is still running and expanding. Because the recruiters recycle contact profiles and infrastructure, agencies expect the same tactics to keep surfacing under different names. For organizations that already rely on remote contractors, the practical takeaway is that a hiring decision can now carry a security consequence: bring on the wrong candidate and you may bring on their backdoor.

The pattern here mirrors what small scientific and technical organizations face from infrastructure attacks, a risk that grew sharply in 2026 when cyberattacks grounded everything from meteor-tracking nonprofits to utility providers. When a group relies on volunteer labor and lightly staffed IT, a single compromised machine can cascade into a much larger outage or data loss, exactly as the WaterPlum recruiters intend when they plant a RAT on a jobseeker's device.

Why This Scheme Is Different

The recruiter campaign is the mirror image of a better-known North Korean tactic. For years, the regime has placed its own IT workers in technology roles at Western and allied companies, often with the help of accomplices running laptop farms that make remote workers appear to be based in the country where they were hired.

WaterPlum runs that playbook in reverse. Instead of sending a North Korean operator into your company, it pulls a legitimate applicant into an attacker-controlled machine. The two approaches feed each other. A stolen identity from a WaterPlum infection can be reused to place a fraudulent worker. A compromised device can be used to compromise the company that later hires the applicant.

Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. The sprawling IT worker fraud is thought to net the regime upwards of $500 million a year, much of it surrendered to the state from salaries paid by companies in countries that impose heavy sanctions on North Korea.

What WaterPlum Actually Steals

The advisory itemizes what the backdoored computers hand over:

  • Intellectual property and trade secrets from current or future employers.
  • Credentials and passwords stored on the device.
  • Clipboard contents and keystrokes.
  • Cryptocurrency wallet data and private keys.
  • Identity documents that can support further impersonation.
Key stat: The four-nation advisory attributes at least $10.71 million in thefts to WaterPlum, with proceeds flowing to Pyongyang.

That last category is the multiplier. A stolen passport or driver's license does not just expose one victim. It becomes the foundation for the fake-IT-worker pipeline, letting a regime operator pose as a real person during interviews with legitimate companies. Every device infected is potentially both a theft and a source of identities for the larger operation.

The Warning Signs Employers Miss

Because the scheme depends on victims opening files, the most important defenses are on the applicant side. But the advisory also flags signs that help employers spot a fraudulent North Korean candidate, whether from the recruiter variant or the worker variant:

  • Resumes that claim prestigious educational backgrounds and extensive experience that do not survive scrutiny.
  • Repeated refusals to meet in person.
  • Suspicious interruptions to video feeds, or voices in the background.
  • Requests for payment in cryptocurrency.
  • Use of AI face-swapping software that produces visual artifacts during calls, prompting the applicant to disable the camera shortly after the interview begins.
What competitors missed: The advisory cannot say how many of the 30,000 infections have already been leveraged to place fake IT workers in corporate roles, because the operations deliberately cross the boundaries between recruiting, identity theft, and employment fraud.

A Pattern, Not an Anomaly

WaterPlum is the latest chapter in a documented pattern of North Korean cyber operations that blend employment fraud with financial theft. The same RAT techniques resurfaced in North Korean IT worker scams in 2025, and the underlying fake-worker economy has been running for years. The scale is industrial:

Metric Value
Devices infected by WaterPlum 30,000+
Cryptocurrency wallets compromised 7,000+
Theft attributed to WaterPlum $10.71 million
North Korean IT workers worldwide ~100,000
Estimated annual regime revenue $500 million+

The throughline is not sophistication. It is scale and patience. The regime has built a pipeline that monetizes identity theft, credential theft, and employment fraud at the same time. WaterPlum is the recruitment front of that pipeline, and the advisory makes clear the front is being expanded, not dismantled.

What to Do Now

If you are a jobseeker in web development, engineering, or crypto and Web3:

  • Treat unsolicited recruiter outreach that immediately demands you download a file with suspicion.
  • Run any downloaded coding test in a sandboxed, isolated environment rather than on your main machine.
  • Keep your operating system and antivirus current, and enable endpoint detection where possible.
  • Never let a "recruiter" remote into your computer, and never paste wallet private keys into a session.
Bottom line: WaterPlum is the recruitment front of a North Korean identity-theft and employment-fraud pipeline. More than 30,000 devices are infected, 7,000 cryptocurrency wallets have been compromised, and the proceeds are funding the regime. The defense is the same on both sides of the table: verify the recruiter, isolate the file, and treat a coding assignment like what it is, untrusted code from an unknown sender. The same discipline that keeps a single compromised laptop from cascading into a full organizational breach is what the WaterPlum recruiters are counting on you to skip. For more on how a single weak entry point can take down an entire volunteer-run operation, see our breakdown of the [cyberattack that grounded meteor trackers](https://www.unboxfuture.com/2026/09/cyberattack-grounds-meteor-trackers-imo_024067697.html).

Sources & Verifications

  1. The Register (Connor Jones, September 18, 2026): WaterPlum infected 30,000 devices, compromised 7,000 crypto wallets, $10.71 million attributed, four-nation advisory, warning signs. https://www.theregister.com/security/2026/09/18/north-koreas-fake-job-interviews-infected-30000-devices/5297461
  2. IC3 Internet Crime Complaint Center (September 18, 2026): joint advisory on WaterPlum recruitment campaign; goals and theft categories. https://www.ic3.gov/CSA/2026/260918.pdf
  3. The Register (September 25, 2025): Lazarus RAT code resurfacing in North Korean IT worker scams. https://www.theregister.com/security/2025/09/25/lazarus-rat-code-resurfaces-in-north-korean-it-worker-scams/1162142
  4. The Register (March 18, 2026): estimate of 100,000 fake IT workers netting $500 million a year for North Korea. https://www.theregister.com/security/2026/03/18/north-koreans-100k-fake-it-workers-net-500m-a-year-for-kim/5224468

Post a Comment

Previous Post Next Post